What is Azure DDoS Protection?
Azure DDoS Protection protects applications from volumetric, protocol-based, and application-layer attacks. Every Azure resource with a public IP address is automatically and freely protected by the Basic infrastructure protection tier. For higher protection requirements, Microsoft offers the paid tiers DDoS IP Protection and DDoS Network Protection (formerly “DDoS Protection Standard”) with application-specific, adaptive protection.
Core Features
- Always-on traffic monitoring and automatic L3/L4 attack detection
- Adaptive tuning of mitigation policies based on the application profile
- Attack analytics, mitigation reports, and flow logs
- DDoS Network Protection additionally includes: rapid response support, cost protection for documented attacks, and a WAF discount
- Integration with Azure Monitor, Microsoft Sentinel, and Azure Firewall Manager
Typical Use Cases
- Protection of publicly accessible web applications and APIs
- Gaming platforms and services with high, volatile traffic
- Financial services providers and other regulated industries with elevated availability requirements
Benefits
- No performance impact during normal operation
- Automatic detection and mitigation without manual configuration
- Scalable pricing: start with IP Protection, get the full feature set with Network Protection
- Native integration with Azure network and security services
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you with Azure DDoS Protection: choosing the right protection tier, architecture review, implementation, and incident response and optimization of protection profiles.
Frequently Asked Questions
What protection levels does Azure DDoS Protection offer?
Basic (infrastructure protection) is enabled for free for all Azure customers and protects the Azure platform itself. In addition, there are the paid tiers DDoS IP Protection (priced per protected IP address) and DDoS Network Protection (priced per 100 protected IPs, formerly 'Standard'), which add rapid response support, cost protection, and a WAF discount.
What's the difference between IP Protection and Network Protection?
Both paid tiers offer adaptive detection, attack analytics, and application-tuned mitigation policies. DDoS Network Protection additionally includes rapid response support, a cost guarantee for DDoS-related scale-out costs, and a WAF discount, which DDoS IP Protection does not offer.
How does adaptive detection work?
Machine learning analyzes an application's normal traffic patterns and detects anomalies. When an attack is detected, mitigation is activated automatically without manual intervention.
What does the cost guarantee cover?
With DDoS Network Protection, customers receive service credits for documented, DDoS-related scale-out costs (e.g., additional VM or bandwidth costs). Exact terms are defined in Microsoft's official cost protection documentation.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
